Adobe Coldfusion vulnerabilities
257 known vulnerabilities affecting adobe/coldfusion.
Total CVEs
257
CISA KEV
17
actively exploited
Public exploits
23
Exploited in wild
28
Severity breakdown
CRITICAL74HIGH81MEDIUM93LOW9
Vulnerabilities
Page 3 of 13
CVE-2017-11283P2CRITICALCVSS 9.8v11.0v20162017-12-01
CVE-2017-11283 [CRITICAL] CWE-502 CVE-2017-11283: Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earl
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
nvd
CVE-2017-11284P2CRITICALCVSS 9.8v11.0v20162017-12-01
CVE-2017-11284 [CRITICAL] CWE-502 CVE-2017-11284: Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earl
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
nvd
CVE-2022-38421P2HIGHCVSS 7.2v2018v2021+1 more2022-10-14
CVE-2022-38421 [HIGH] CWE-22 CVE-2022-38421: Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Impr
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but does require admi
nvd
CVE-2019-7839P2CRITICALCVSS 9.8v11.0v2016+2 more2019-06-12
CVE-2019-7839 [CRITICAL] CWE-77 CVE-2019-7839: ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a co
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2026-48319P2CRITICALCVSS 9.1v2023v2023-update1+31 more2026-07-14
CVE-2026-48319 [CRITICAL] CWE-22 CVE-2026-48319: ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trav
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user inte
nvd
CVE-2025-43561P2CRITICALCVSS 9.1v2021v2023+2 more2025-05-13
CVE-2025-43561 [CRITICAL] CWE-863 CVE-2025-43561: ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not req
nvd
CVE-2026-27305P2HIGHCVSS 8.6v2023v2023-update1+24 more2026-04-14
CVE-2026-27305 [HIGH] CWE-22 CVE-2026-27305: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issu
nvd
CVE-2019-7091P2CRITICALCVSS 9.8v11.0v2016+2 more2019-05-24
CVE-2019-7091 [CRITICAL] CWE-502 CVE-2019-7091: ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a des
ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-15957P2CRITICALCVSS 9.8v11.0v2016+2 more2018-09-25
CVE-2018-15957 [CRITICAL] CWE-502 CVE-2018-15957: Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2025-30281P2CRITICALCVSS 9.1v2021v2023+2 more2025-04-08
CVE-2025-30281 [CRITICAL] CWE-284 CVE-2025-30281: ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, a
nvd
CVE-2022-38419P2HIGHCVSS 7.5v2018v2021+1 more2022-10-14
CVE-2022-38419 [HIGH] CWE-611 CVE-2022-38419: Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Impr
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.
nvd
CVE-2019-7840P2CRITICALCVSS 9.8v11.0v2016+2 more2019-06-12
CVE-2019-7840 [CRITICAL] CWE-502 CVE-2019-7840: ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a de
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-15959P2CRITICALCVSS 9.8v11.0v2016+2 more2018-09-25
CVE-2018-15959 [CRITICAL] CWE-502 CVE-2018-15959: Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-15965P2CRITICALCVSS 9.8v11.0v2016+2 more2018-09-25
CVE-2018-15965 [CRITICAL] CWE-502 CVE-2018-15965: Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-15958P2CRITICALCVSS 9.8v11.0v2016+2 more2018-09-25
CVE-2018-15958 [CRITICAL] CWE-502 CVE-2018-15958: Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2025-43560P2CRITICALCVSS 9.1v2021v2023+2 more2025-05-13
CVE-2025-43560 [CRITICAL] CWE-20 CVE-2025-43560: ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validatio
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require
nvd
CVE-2016-1114P2CRITICALCVSS 9.8v10.0v11.0+1 more2016-05-11
CVE-2016-1114 [CRITICAL] CWE-502 CVE-2016-1114: Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote att
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
nvd
CVE-2026-48281P2CRITICALCVSS 10.0v2023v2023-update1+29 more2026-06-30
CVE-2026-48281 [CRITICAL] CWE-20 CVE-2026-48281: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnera
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2026-48276P2CRITICALCVSS 10.0v2023v2023-update1+29 more2026-06-30
CVE-2026-48276 [CRITICAL] CWE-434 CVE-2026-48276: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2026-48283P2CRITICALCVSS 10.0v2023v2023-update1+29 more2026-06-30
CVE-2026-48283 [CRITICAL] CWE-434 CVE-2026-48283: ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
nvd